Debian DSA-109-1 : faqomatic - XSS vulnerability

medium Nessus Plugin ID 14946

Synopsis

The remote Debian host is missing a security-related update.

Description

Due to unescaped HTML code Faq-O-Matic returned unverified scripting code to the browser. With some tweaking this enables an attacker to steal cookies from one of the Faq-O-Matic moderators or the admin.

Cross-Site Scripting is a type of problem that allows a malicious person to make another person run some JavaScript in their browser.
The JavaScript is executed on the victims machine and is in the context of the website running the Faq-O-Matic Frequently Asked Question manager.

Solution

Upgrade the faqomatic package if you have it installed.

This problem has been fixed in version 2.603-1.2 for the stable Debian distribution and version 2.712-2 for the current testing/unstable distribution.

See Also

http://www.debian.org/security/2002/dsa-109

Plugin Details

Severity: Medium

ID: 14946

File Name: debian_DSA-109.nasl

Version: 1.18

Type: local

Agent: unix

Published: 9/29/2004

Updated: 1/4/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.5

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:faqomatic, cpe:/o:debian:debian_linux:2.2

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Patch Publication Date: 2/13/2002

Reference Information

CVE: CVE-2002-0230

DSA: 109